{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:16:24.610Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Celebrity iCloud photo theft: 600 victims phished with fake Apple and Google emails","date":"2014-09","date_precision":"month","victim_org":"Celebrities and private individuals with Apple iCloud and Google accounts","sector":"Consumer","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement.","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_note":"No monetary loss figure was published; harm was the public leak of private photographs.","records_affected":600,"threat_actor":"Ryan Collins (convicted)","summary":"The 2014 mass leak of private celebrity photographs, widely reported as an iCloud hack, was in fact a credential phishing campaign. Ryan Collins of Lancaster, Pennsylvania sent emails that appeared to come from Apple or Google asking recipients for their usernames and passwords, then used the harvested credentials to access more than 100 accounts including at least 50 iCloud and 72 Gmail accounts. Investigators identified over 600 victims. Collins was sentenced on 26 October 2016 to 18 months in federal prison.","how_it_worked":"Collins sent messages that mimicked Apple and Google account security notices, using the vendors' visual conventions and a plausible security pretext to make responding feel like protecting the account rather than surrendering it. Victims replied with, or entered, their account usernames and passwords. Collins then signed in directly and downloaded the full contents of iCloud backups, which on Apple devices at that time included the entire camera roll and message history. No platform vulnerability was exploited; the whole compromise rested on the victim voluntarily supplying credentials to a convincing imitation of the provider.","lessons":"Mandatory two-factor authentication on consumer cloud backup accounts, and provider policies that never request passwords by email, would have neutralised the harvested credentials.","confidence":"Confirmed","sources":[{"title":"Pennsylvania Man Sentenced to 18 Months in Federal Prison for Hacking Apple and Google E-Mail Accounts","url":"https://www.justice.gov/usao-cdca/pr/pennsylvania-man-sentenced-today-18-months-federal-prison-hacking-apple-and-google-e","publisher":"U.S. Department of Justice"}],"entry_type":"incident","slug":"2014-celebrity-icloud-photo-theft-600-victims-phished-with-fake-apple-and-goo","year":2014,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-celebrity-icloud-photo-theft-600-victims-phished-with-fake-apple-and-goo"}]}